Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » (PoC) code for Google Toolbar Phishing/Malicious Code
Search Topic:
Uniqs:
128
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
WIndows Live OneCare Upgrade to 2.0? »
« Trojan bumps Google ads from Web pages  
AuthorAll Replies


Woody79_00

join:2004-07-08
united state

(PoC) code for Google Toolbar Phishing/Malicious Code

The Google toolbar has found yet another use: as a possible malware vector. A researcher has released a proof-of-concept (PoC) code, which demonstrates how an attacker may install malicious software or conduct phishing attacks by prompting the user to install a new Google toolbar button.

Affected Google toolbar versions are as follows:

Google Toolbar 5 beta for Internet Explorer
Google Toolbar 4 for Internet Explorer
Google Toolbar 4 for Firefox (partially)
The code makes use of a specially crafted link that refers to the button’s XML file, which when clicked displays a dialog box summarizing the details of the button to be installed. This dialog box also displays a URL of where the button is to be downloaded. Through manipulation, however, a malicious author could make it appear that the said URL is non-malicious by adding special redirector strings.

»blog.trendmicro.com/google-toolb···buttons/
Forums » Up and Running » Security » SecurityWIndows Live OneCare Upgrade to 2.0? »
« Trojan bumps Google ads from Web pages  


Wednesday, 09-Dec 01:58:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [193] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [50] The Future Of Wi-Fi Is Bright
· [49] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [20] AT&T Releases Network Reporting iPhone App
Most people now reading
· Comcast refused to install 400' feet. [Comcast HSI]
· Man Downloads Child Porn "Accidentally," Faces 20 Years [Security]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· [ Classes] ATTN Death Knights - Post your spec for critique! [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Servers UP!!! [World of Warcraft]
· [Signals] 750ft, can it be done? [Comcast HSI]
· Tomato/MLPPP v3 alpha 6 released! [TekSavvy]
· Errrybody must be stuck home from the snow [Mediacom]